AIO Glossary Flashcards
A tool that sites between client systems and the back end services they call via API rwquests in order to serve as a reverse proxy for security and performance capabilities
API Gateway
A set of functions, routines, tools or protocols for building applications. An API allows for interaction between systems and applications that can be leveeraged by developers as building blocks for their applications and data access through a common method, without custom coding for each integration
Application Programming Interface (API)
An estimated number of the times a threat will successfully exploit a given vulnerability over the couse of a single year
Annualized Rate of Occurrence (ARO)
A threat modeling approach composed of Architecture, Threats, Attack Surfaces and Mitigations
ATASM
The ability to properly capture, analyze and report on any and all events that happen within a system or application, such as data access and modification, user actions and processes, controls and compliance and regulatory and contractual compliance
Auditability
The process of evaluating credentials presented by a user, application or service to prove its identity as compared to values already known and verified by the authentication system
Authentication
The process of granting or denying access to a system, network or application after successful authentication has been performed, based on approved criteria set by regulation
Authorization
Part of the change management process, which establishes an agreed upon standard configuration and the attributes that comprise it and forms the basis for managing change from that point forward
Baseline
A heavily fortified system that serves as a jumpbox or proxy between an untrsuted network and trusted networks
Bastion Host
The capability of an organization to continue the operation of systems or applications at a predetermined level after an incident or a disruption of service
Business Continuity
A process designed to identify risks, threats and vulnerabilities that could disrupt or impact services, with the intent of determining mitigation stratgies and response processes should they occur
Business Continuity Management
A developed and tested document, containing information from stakeholders and staff, for the continuation of operations and services in the event of a disruption or incident
Business Continuity Plan
A structured methodology to identify and evaluate the possible risks and threats that operations or services could be impacted by, as well as the possible or liklely extent of impact and disruption
Business Impact Analysis
The formal documentiation showing the chronological control and disposition of data or evidence, either physical or electronic. This documentation includes creation, all changes of possession and final disposition.
Chain of Custody
Federation
A group of IT service providers that interoperate based on an agreed upon set of standards and operations
An individual with a role in the change management process who ensures the overall change process is properly executed. This person also directly handles low levels tasks related to the change process
Change Manage
A software tool or service that sits between cloud resources and the clients or systems accessing them. It serves as a gateway that can perform a variety of security and policy enforcement functions. A CASB typically can consolidate and perform the functions of firewalls and web applications firewalls as well as provide authentication and data loss prevention capabilities
Cloud Access Security Broker
An application that is never installed on a local server or desktop but is instead accessed via a network or the Internet. A cloud application merges the functionalty of a local application with the accessibility of a web based application
Cloud Application
Cloud Application Management for Platforms (CAMP)
Within a PaaS implementation, CAMP servers as the framework and specification for managing platform services, encompassing a RESTful protocol for managing services, the model for describing and documenting the components that comprise the platform, and the language describing the overall platform, its components and services and the metadata about it
An audit that is specifically responsible for conducting audits of cloud systems and cloud applications. The cloud auditor is responsible for assessing the effectiveness of cloud service and identifying control deficiencies between the cloud customer and the cloud provider, as well as the cloud broker if one is used
Cloud Auditor
The process of using a cloud based backup system, with files and data being sent over the network to a public or private cloud provider for backup, rather than running traditional backup systems within a data center
Cloud backup
A public or private cloud services organization that offers backup services to either the public or organizational clients, either on a free basis or using various costing models based on either the amount of data or number of systems
Cloud Backup Service Provider
Services that run within a public or private cloud offering backup solutions, either through client based software that does automatic or scheduled backups or through manual backups initiated by a user or system
Cloud Backup Solutions
An organization that sells and offers cloud services, and possibly cloud support services, to various organizations and works as a middleman between the cloud customer and cloud provider
Cloud Computing Reseller